Updated perl-DBI packages fix security vulnerabilities
Publication date: 09 Sep 2026Modification date: 09 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-73193 , CVE-2026-73194
Description
DBI versions before 1.652 for Perl allow a heap out-of-bounds write on
32-bit perl via an integer wraparound in the output buffer size computed
by preparse.
DBI versions before 1.652 for Perl allow a heap out-of-bounds write via
an unvalidated numeric placeholder that sets the binder counter in
preparse.
References
- https://bugs.mageia.org/show_bug.cgi?id=36144
- https://www.openwall.com/lists/oss-security/2026/08/15/2
- https://github.com/perl5-dbi/dbi/security/advisories/GHSA-wj3v-c3hh-mhqr
- https://www.openwall.com/lists/oss-security/2026/08/15/3
- https://github.com/perl5-dbi/dbi/security/advisories/GHSA-623j-hfpc-mrc4
- https://www.cve.org/CVERecord?id=CVE-2026-73193
- https://www.cve.org/CVERecord?id=CVE-2026-73194
SRPMS
10/core
- perl-DBI-1.652.0-2.mga10
9/core
- perl-DBI-1.652.0-1.1.mga9